You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
on different architectures (specifically x32 vs x64) the sizes and layouts of structures will differ. right now, capa doesn't have an easy way to limit its offset features based on the architecture, which means there's a greater chance of FP binaries of the wrong bitness. we should consider extending the offset features with tags specifying what bitnesses they match.
on different architectures (specifically x32 vs x64) the sizes and layouts of structures will differ. right now, capa doesn't have an easy way to limit its offset features based on the architecture, which means there's a greater chance of FP binaries of the wrong bitness. we should consider extending the offset features with tags specifying what bitnesses they match.
initially motivated here: mandiant/capa-rules#54 (comment)
best sketch so far:
this would be an easy add, since we could just emit an additional feature for each offset that's tagged with the bitness.
The text was updated successfully, but these errors were encountered: